A solution that worked for me was to login to vCenter with an account that is part of
“Administrators” group that you see in the dbo.pd_acedata table. That
group is actually the local Administrators group on the local server itself –
it’s not the Administrators group of domain (which will show up as
CONTOSOAdministrators) or part of vCenter SSO. So, I logged in as a local
server user that was part of that Administrators group (in my case it was a renamed
account from the original Administrator account) and was able to load SRM
plugin. From there I went to permissions tab and added the domain group that
should have correct permissions and was then able to login SRM with a domain
user that was part of that domain group as expected. If you are able to fix it this
way, you don’t need to fumble with SQL entries.